fix: 口令文件默认值回到仓库根(按你的决定),并让相对路径与工作目录无关
你的决定:口令文件继续放在仓库根,靠 .gitignore 的 *.key 兜住"不被提交"。我把出厂默认值改回 baknret.key,并把配置注释从"必须放在仓库之外"改成如实说明这是一次取舍:省事 vs 「不提交」依赖一个规则文件(git add -f、或整目录复制到别处再初始化仓库时,口令会跟着走)。 顺手修掉一个潜在陷阱:口令文件写相对路径时,原先的 Test-Path 是按**当前工作目录**找的。计划任务的工作目录通常是 C:\Windows\System32,在那里 Test-Path baknret.key 为假,加密条目就会以"拿不到口令"失败 —— 而配置看上去毫无问题。现在相对路径按仓库根解析(复用上一轮抽出来的 Resolve-BakNRetRootedPath)。 证据:把工作目录切到 C:\Windows\System32 再跑真实清单只读冒烟,仍然 4/4 通过(那份真实配置里有 5 个加密条目、口令文件就是仓库根的 baknret.key)。 验收:test.ps1 9/9 全绿(7 与 5.1)。
This commit is contained in:
1 parent
120cf3584b
commit
520257b5e5
3 files changed
+17
-3
No files matched your search
@@ -162,6 +162,11 @@ $manifest = Read-BakNRetManifest -Path $manifestPath
|
|||||||
$manifest.compressor = [pscustomobject]@{ name = $tool.Name; command = $tool.Command; extension = $tool.Extension; version = $toolVersion }
|
$manifest.compressor = [pscustomobject]@{ name = $tool.Name; command = $tool.Command; extension = $tool.Extension; version = $toolVersion }
|
||||||
|
|
||||||
$passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile }
|
$passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile }
|
||||||
|
if ($passwordFile) {
|
||||||
|
# 相对路径按**仓库根**解析,而不是按当前工作目录:计划任务的工作目录是 C:\Windows\System32,
|
||||||
|
# 在那里 Test-Path 找不到 baknret.key,加密条目就会以"拿不到口令"失败,而配置看上去没问题。
|
||||||
|
$passwordFile = Resolve-BakNRetRootedPath -Path $passwordFile -Default $passwordFile -Root $PSScriptRoot
|
||||||
|
}
|
||||||
$password = Get-BakNRetPassword -PasswordFile $passwordFile
|
$password = Get-BakNRetPassword -PasswordFile $passwordFile
|
||||||
$encryptAll = [bool]$script:Config.Encryption.Enabled
|
$encryptAll = [bool]$script:Config.Encryption.Enabled
|
||||||
$showToolOutput = (-not $QuietTool) -and ($script:Config.ToolOutput -ne 'quiet')
|
$showToolOutput = (-not $QuietTool) -and ($script:Config.ToolOutput -ne 'quiet')
|
||||||
|
|||||||
+7
-3
@@ -49,15 +49,19 @@
|
|||||||
# 口令本身按以下优先级获取(见 README「加密」):
|
# 口令本身按以下优先级获取(见 README「加密」):
|
||||||
# 1. -Password 命令行参数
|
# 1. -Password 命令行参数
|
||||||
# 2. $env:BAKNRET_PASSWORD
|
# 2. $env:BAKNRET_PASSWORD
|
||||||
# 3. PasswordFile 指向的文件首行 —— 必须指向仓库**之外**的文件;
|
# 3. PasswordFile 指向的文件首行 (首行即口令)
|
||||||
# 出厂默认值留空:默认值指向仓库里的某个文件,等于鼓励把口令放进版本库
|
#
|
||||||
|
# 出厂默认值就是仓库根的 baknret.key,靠 .gitignore 的 *.key 兜住「不被提交」。
|
||||||
|
# 这是**取舍**而非疏忽:留在仓库根最省事(口令与配置在一起,搬家不容易丢),代价是
|
||||||
|
# 「不提交」这件事依赖一个规则文件 —— 谁写了 git add -f、或把整个目录复制到别处再
|
||||||
|
# 初始化仓库,口令就会跟着走。要更稳就把文件放到仓库外,用下面的 B 或 A。
|
||||||
# 4. 交互式询问(仅交互式会话;计划任务里不会停下来等输入)
|
# 4. 交互式询问(仅交互式会话;计划任务里不会停下来等输入)
|
||||||
# 全都拿不到时该条目明确失败,绝不退化成明文归档。
|
# 全都拿不到时该条目明确失败,绝不退化成明文归档。
|
||||||
#
|
#
|
||||||
# 注意 7z 只接受命令行口令,口令在本机进程列表里短暂可见,这是 7z 本身的限制。
|
# 注意 7z 只接受命令行口令,口令在本机进程列表里短暂可见,这是 7z 本身的限制。
|
||||||
Encryption = @{
|
Encryption = @{
|
||||||
Enabled = $false
|
Enabled = $false
|
||||||
PasswordFile = ''
|
PasswordFile = 'baknret.key'
|
||||||
EncryptHeaders = $true
|
EncryptHeaders = $true
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -115,6 +115,11 @@ if (-not $WhatIfPreference -and -not $VerifyOnly) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
$passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile }
|
$passwordFile = if ($KeyFile) { $KeyFile } else { $script:Config.Encryption.PasswordFile }
|
||||||
|
if ($passwordFile) {
|
||||||
|
# 相对路径按**仓库根**解析,而不是按当前工作目录:计划任务的工作目录是 C:\Windows\System32,
|
||||||
|
# 在那里 Test-Path 找不到 baknret.key,加密条目就会以"拿不到口令"失败,而配置看上去没问题。
|
||||||
|
$passwordFile = Resolve-BakNRetRootedPath -Path $passwordFile -Default $passwordFile -Root $PSScriptRoot
|
||||||
|
}
|
||||||
$password = Get-BakNRetPassword -PasswordFile $passwordFile
|
$password = Get-BakNRetPassword -PasswordFile $passwordFile
|
||||||
|
|
||||||
# ============================================================================
|
# ============================================================================
|
||||||
|
|||||||
Reference in new issue
Block a user